CISA said ransomware gangs are actively exploiting CVE-2025-60710, a high-severity Windows Task Host privilege escalation vulnerability affecting Windows 11 and Windows Server 2025. The bug stems from CWE-59 improper link resolution, or "link following," and allows a local attacker with basic user privileges to gain SYSTEM access on unpatched devices. Microsoft released a fix for the flaw in November 2025, while CISA previously added it to the Known Exploited Vulnerabilities catalog before updating the entry to note ransomware abuse.
CISA has not disclosed technical details about the attacks, and Microsoft had not updated its advisory at the time of reporting to confirm observed exploitation in the wild. Federal Civilian Executive Branch agencies were ordered to remediate the issue within two weeks, underscoring the urgency of patching systems exposed to the vulnerability. The disclosure also fits a broader pattern of ransomware operators targeting Microsoft product flaws, including the recently exploited SharePoint vulnerability CVE-2026-45659.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
CISA later updated the KEV entry for CVE-2025-60710 to state that ransomware gangs are abusing the vulnerability. The agency also directed Federal Civilian Executive Branch agencies to remediate the issue within two weeks.
Microsoft released a patch for CVE-2025-60710, a high-severity Windows Task Host privilege escalation vulnerability affecting Windows 11 and Windows Server 2025. The flaw is caused by a link-following weakness that can let a local attacker with basic user permissions gain SYSTEM privileges.
CISA added CVE-2025-60710 to its Known Exploited Vulnerabilities catalog and initially flagged it as actively exploited. The agency identified the Windows Task Host flaw as posing significant risk to federal systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
5 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcebleepingcomputer.com
Open sourcecisa.gov
Open sourcecwe.mitre.org
Open sourcecve.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.